Humanoid robots and the safety question

NVIDIA’s new robotics safety system is a welcome step for an industry that has under-invested in safety. However, it also points to a harder problem that humanoid robots have yet to solve: what happens when a component fails. Machinery & Manufacturing hears from David Brandt, VP of R&D and CTO at Teradyne Robotics.
NVIDIA recently announced ‘Halos for Robotics’, which it describes as the industry’s first full-stack safety system for physical AI. The system brings the company’s autonomous vehicle safety work into the world of robots. Agility Robotics is the first to build NVIDIA Halos for Robotics into its humanoid robot, Digit. When one of the most influential companies in computing puts its weight behind robot safety – and when a leading humanoid maker submits its system for independent scrutiny – the whole field benefits.
Investment in safety is investment in trust. It’s therefore worth looking closely at what this wave of work addresses, and what it doesn’t.
A perception problem
Most of the safety effort around humanoids concentrates on perception. The hard questions are framed as ‘can the robot detect people, predict where they’re going and avoid a collision?’ NVIDIA’s approach includes an ‘outside-in’ method that uses external cameras and AI agents to watch the workspace and adjust robot behaviour accordingly.
However, perception-based collision avoidance rests on an assumption that the robot retains self-control. The discipline of functional safety is built on the opposite instinct. A risk assessment spends less time on how a machine behaves when everything works, and more on how it behaves when something breaks. The central question, therefore, is what the robot does the moment one of its parts fails.
The part failure question
A legged humanoid stays upright by continuously sensing its own balance and compensating, many times a second. Take that control away and it falls.
Picture a humanoid mid-stride when an actuator in one leg fails. Given the mass of these robots and their high centre of gravity, the potential consequences are serious. A flawless perception system is no help here; the robot might know the location of people but will be unable to avoid them. By the time the fault occurs, the robot has lost the very control that perception was meant to inform.
And here’s a related point about power: a battery fault can disable every actuator and sensor at once, and a humanoid needs a reserve of power.
Stability ultimately depends on nothing going wrong, which makes fault tolerance a deeper safety challenge for human-shaped robots.
Meeting the rule book
Industrial robots are typically designed to be single-fault tolerant in order to meet relevant safety standards. In plain terms, no single component failure should create a dangerous situation. ISO 10218-1, the standard for industrial robot arms, is built on that principle.
Apply the same requirement to a heavy, dynamically stable machine and you’re left with two options. The first is to engineer actuators, sensors and battery management systems that are either fully redundant or so reliable they almost never fail. How to do that at an acceptable cost currently eludes me.
The second option is to accept that working alongside a humanoid carries more risk than working alongside a conventional industrial robot.
ISO 10218-1 does not address the risks created by a humanoid’s own mobility. The first standard written specifically for dynamically stable mobile robots, ISO/CD 25785-1, is still at committee-draft stage, working through its first round of comments. The safety case is therefore unfinished, and the honest version of that case is more demanding than the current conversation suggests.
Benefits of purpose-built
A collaborative robot arm mounted on a wheeled autonomous base does not face these problems because it’s statically stable thanks to a heavy base, low centre of gravity and no need to balance. When something goes wrong, the safe response is simple: cut the power and apply the brakes. A machine standing still is rarely a danger to anyone.
That difference is the result of choosing a form factor for the task rather than for its resemblance to us. Autonomous mobile robots, collaborative arms and the standards-driven safety functions behind them were designed so that failure modes are predictable and safe states are easy to reach. The robot’s safety does not hinge on a perception system continuing to work. It’s built into the architecture before any software runs.
There’s another reason that means purpose-built automation will keep winning on the factory floor. The complexity that makes a humanoid captivating in a demonstration is the same complexity that multiplies its failure modes. In manufacturing, reliability is non-negotiable, and falling short means downtime, rework and risk.
Humanoids are not the only way to harness the incredible potential of physical AI on the shop floor. A rapidly growing number of AI-enabled applications are running on collaborative industrial robots and autonomous mobile robots handling machine tending, palletising, inspection and material movement with the safety and reliability factories demand.
New era for robot safety
I welcome NVIDIA’s move and hope it marks the start of a more serious, better-resourced era for robot safety. The more rigour the industry brings, the better for every company building machines that share space with people, mine included.
However, anyone evaluating a humanoid for real work should start with the important, unglamorous question. Before asking whether the robot can recognise a worker, ask what it does when an actuator, sensor or battery fails mid-task. Ask for the stability and reliability data. Ask which standards the system is certified against, and which parts of its operation those standards actually cover.
We had this debate, rightly, about self-driving cars: an open and public discussion about how much risk is acceptable and who decides. Humanoids deserve the same scrutiny. Until the field can answer the failure question as confidently as it answers the perception question, the proven path remains the one the industry has been building for years: robots whose shape and safety are designed for the job.
